Your data
If you’ve dealt with one of our customers
You may never have heard of Sterling Trace, and yet we may hold some of your data. This page explains why that can happen, what we do with it, what we will never do with it, and the rights you have. It exists for you — the supplier, customer or correspondent of a business that uses Sterling.
Who we are
The proof-of-concept service presented under the placeholder display name below operates Sterling — an AI bookkeeper that small businesses use to keep their accounting records and prepare their tax filings.
Proof-of-concept identity notice
These particulars are POC placeholders only. They must be replaced or omitted before charging customers or relying on these pages as final legal particulars.
- Display name: Sterling Trace (POC placeholder).
- Company number: 00000000 — POC placeholder; not a real company registration.
- Address: 1 Prototype Way, London, SW1A 1AA, United Kingdom — POC placeholder; not a registered office.
- Contact email: poc-contact@example.invalid — POC placeholder; non-deliverable placeholder.
- VAT number: GB000000000 — POC placeholder; not a VAT registration.
These fixtures do not establish that Sterling Trace is incorporated or VAT-registered.
Why we might hold your data when you never gave it to us
Our customers connect their own business records to Sterling, and business records are full of other people. If you have dealt with a business that uses Sterling, your data can reach us through:
- Their mailbox — if you emailed them, or they emailed you, Sterling may have read that correspondence: your name, email address, what the messages say, and any attachments.
- Their bank account — if you paid them or they paid you, your name can appear in the transaction record.
- The public register — if you are an officer or person with significant control of a company they looked up, Sterling may have read your Companies House particulars.
- Documents they sent Sterling directly — invoices, receipts and paperwork that mention you.
What we do with it — and what we never do
One thing only: we use it to keep our customer’s accounting records and prepare their filings, which the law requires them to do. An invoice you sent them is part of their books; that is the beginning and the end of our interest in it.
- We make no decision about you.
- We will not contact you.
- We do not market to you, and never will.
- We do not sell your data or share it with advertisers.
- We do not train AI models on your data.
- Day to day no human reads it at all — Sterling is software, and our staff can only see specific items with the customer’s explicit, recorded, time-limited approval.
Our lawful basis, and why a public notice
We process this data under UK GDPR Article 6(1)(f) — legitimate interests: our customer’s legal duty to keep accounting records, and our role in keeping them. We have made a written assessment weighing those interests against your rights, including what you would reasonably expect — handing business records to a bookkeeper is what businesses have always done, though you should know the bookkeeper here is software and uses the AI providers named below.
The law normally requires a company holding your data to tell you individually. Where that would take disproportionate effort — a single mailbox can contain thousands of correspondents, and an email from an unknown company about your data would be more intrusive than helpful — the law allows a public notice instead, and requires us to publish the information this page contains. This page is that notice.
Who sees it
The same providers that process our customers’ data, listed in full — what each sees and where it runs — in our main privacy policy. Two matter most for your data: xAI (which reads message content, attachments and document images to judge financial relevance) and OpenAI (which processes extracted text and voice audio). Both run in the United States, so data reaching them leaves the UK. Everything at rest is stored with Hetzner in Germany.
How long we keep it
Data that becomes part of a customer’s accounting records is kept as long as the customer uses Sterling and as long as tax law requires those records to exist. When a customer deletes their account, their records — including the data about you inside them — are deleted, less what tax law requires kept. One specific rule: if Sterling detects a password or key in a message, the detected text is erased after 14 days.
Your rights
UK GDPR gives you rights over this data: to object to the processing, and to ask for access, correction, erasure or restriction. If you object or ask for erasure, be aware the law itself may require the customer’s accounting records to be kept for tax purposes — we will tell you honestly what was removed and what had to remain.
How to raise it: the quickest route today is through the Sterling customer you dealt with — because we and they are joint controllers (see below), you can exercise your rights against either of us, and they can raise your request with us directly from their account. If you are unhappy with how your data is handled, you can complain to the Information Commissioner’s Office (ICO).
We and our customer are joint controllers: who does what
For the pipeline that reads connected sources and decides what is relevant to the accounts, Sterling Trace and its customer act as joint controllers, and the law requires the essence of our arrangement to be available to you. It is this:
- We publish this privacy information, answer rights requests about our processing, keep the joint processing secure, and notify the regulator if a breach on our side requires it.
- The customer is responsible for their own use of their records, their own systems, and for having the right to connect the sources they connect.
- You may exercise your rights against either of us, whatever the arrangement says.